Solved

TLS 1.1  Should I use QWORD or DWORD and what ciphers should be added ?

Posted on 2014-11-10
5
293 Views
Last Modified: 2014-11-11
Windows 2008 R2 server, IIS 7.0.  I turned off the SSL 3.0 and turned on the TLS 1.1 in the registiry using the Microsoft instructions.  They scanned the server again and they are saying it's still  vunerable.

I used QWORD in the registry settings instead of DWORD since it's a 64 bit operating system.  Is QWORD Correct?

I was not sure if there were specific ciphers I needed to turn off also that may still be causing the problem?
0
Comment
Question by:kdschool
5 Comments
 
LVL 79

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 100 total points
ID: 40434259
they should be DWORD not QWORD
set-perfectFSecutity.ps1.txt
0
 
LVL 62

Accepted Solution

by:
btan earned 400 total points
ID: 40434303
indeed it is DWORD (32-bit) Value for client and server. And collectively do reference to Microsoft security advisory for the mitigation of the recent SSLv3 Poodle vulnerability. Note there are previous vulnerability such as BEAST which is along the line for disabling SSL v3 too. check out the browser setting and it will be good to push down as GPO to all managed machines and manually configure it for the standalone machine

https://technet.microsoft.com/en-us/library/security/3009008.aspx

You can also catch the screenshot steps below.

https://www.digicert.com/ssl-support/iis-disabling-ssl-v3.htm
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40434472
I gave up using manual registry entries.
Try this free tool instead:

https://www.nartac.com/Products/IISCrypto/

Simon.
0
 
LVL 62

Expert Comment

by:btan
ID: 40434508
there is also some sharing of key note running reg, pls see in SAN posting (esp the feedbacks)
https://isc.sans.edu/forums/diary/POODLE+Turning+off+SSLv3+for+various+servers+and+client/18837
0
 

Author Closing Comment

by:kdschool
ID: 40435786
Can't use a tool through the firewall.  Thank you so much for the images.  That was spot on.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question